Re: How to fix problems with the sashiko review model
James Bottomley <[email protected]> Wed, 22 Jul 2026 11:55:36 -0400
| Newsgroups | dev.linux.lists.ksummit,dev.linux.lists.sashiko-reviews,org.kernel.vger.linux-scsi |
|---|---|
| Message-ID | <9a107be6c6041e3ce892217096c8fba7c9489849.camel@HansenPartnership.com> |
On Wed, 2026-07-22 at 11:39 -0400, Steven Rostedt wrote: > On Wed, 22 Jul 2026 16:25:03 +0200 > Johannes Berg <[email protected]> wrote: >=20 > > There's also a risk thing - if you erroneously get a report for > > SCSI (as you did, IIUC) then you can opt out at that point and not > > worry about it again. > >=20 > > If we erroneously _don't_ get a report for something that didn't > > speak up because they're not on the list, didn't dare say anything, > > didn't pay attention, etc. then nobody ever knows until someone > > starts exploiting it? >=20 > I agree with Johannes here. It's one thing to get an annoying report > that says "You can be compromised by your hardware" when the hardware > is trusted. I have the same issue with boot parameters. But I rather > opt-in than have the case that I'm the odd one out where my hardware > is not trustworthy, but I don't know I have to take action to have it > checked. The thing is it's not just sashiko. Various AI driven patchers seem to be using the prompts, which has lead to a slew of malicious hardware fixes being sent to linux-scsi and I'm getting a bit worn out replying to them saying that's not in our threat model. So I figured why not fix the problem at source. Regards, James